July 2026 Release Notes
Copy link

The Command Platform release notes include information about what’s new, which are updated monthly, and improvements and fixes, which are updated weekly.

ℹ️

Last updated: July 13, 2026

What’s New
Copy link

Learn about new features across the Command Platform. These features were released over the past month and are available now:

Risk
Copy link

Risk is the potential for loss or damage to your assets, operations, or reputation, due to vulnerabilities being exploited by a bad actor. Security teams must assess the risk level by evaluating the likelihood of a threat occurring and the impact that it would have if realized.

Focus remediation efforts with CVE publish date filtering
Copy link

In Attack Surface Management (Surface Command) and Exposure Command, Remediation Hub now includes a CVE Publish Date filter, allowing you to view and filter remediations based on when vulnerabilities were publicly disclosed. This helps you identify newly disclosed threats or long-standing vulnerabilities to prioritize remediation efforts effectively.

With this capability from Risk > Remediation Hub, you can:

  • Prioritize newly disclosed vulnerabilities using CVE publish date filters.
  • Support SLA-driven prioritization and backlog management.
  • Target remediation efforts more effectively based on threat timeline.
  • Align remediation workflows with organizational priorities and deadlines.

Top of page

Surface Microsoft Defender recommendations in Remediation Hub
Copy link

In Attack Surface Management (Surface Command) and Exposure Command, Remediation Hub now includes Microsoft Defender as a third-party remediation source. Customers using the latest Microsoft Defender connector for Attack Surface Management (Surface Command) can view Defender recommendations alongside remediation data from other sources, reducing context switching and helping your team prioritize the highest-impact fixes.

With this capability from Risk > Remediation Hub, you can:

  • View Microsoft Defender remediation recommendations directly in Remediation Hub.
  • Prioritize Defender findings alongside data from other remediation sources.
  • Manage remediation activity in a centralized workflow to reduce context switching.

Top of page

Generate and schedule Top Remediation reports from Remediation Hub
Copy link

In Attack Surface Management (Surface Command) and Exposure Command, Remediation Hub now includes reporting capabilities based on the Vulnerability Management (InsightVM) Top Remediations report. Generate high-level summary and detailed asset-level reports to prioritize actions, understand impacted assets, and share remediation insights across teams. Reports are available on-demand or on a schedule, in PDF, HTML, and CSV formats.

With this capability from Risk > Remediation Hub, you can:

  • Generate summary and asset-level reports on-demand or on a schedule.
  • Share reports in PDF, HTML, and CSV formats with security and IT teams.
  • Automatically deliver scheduled reports to asset owners to reduce manual follow-up.
  • Prioritize remediation across a hybrid environment with data from Vulnerability Management (InsightVM), Cloud Security (InsightCloudSec), and Attack Surface Management.

Top of page

Access Remediation Hub with Vulnerability Management (InsightVM) role-based permissions
Copy link

In Attack Surface Management (Surface Command) and Exposure Command, Remediation Hub is now available to all Vulnerability Management (InsightVM) users — no administrator privileges required. Role-based permissions ensure each user sees only the assets and remediations they are authorized to access, so asset owners can act on prioritized remediations for their assigned assets without relying on security team intervention.

With this capability from Risk > Remediation Hub, you can:

  • Access Remediation Hub as any Vulnerability Management (InsightVM) user.
  • View only the assets and remediations within your authorized scope.
  • See filters and metrics that automatically reflect your assigned asset data.

Top of page

Monitor remediation workflow activity in Remediation Hub
Copy link

In Attack Surface Management (Surface Command) and Exposure Command, Remediation Hub now surfaces workflow activity directly, giving security teams visibility into which workflows have run, execution counts, status, and related artifacts such as Jira tickets and ServiceNow incidents — without leaving the remediation workflow.

With this capability from Risk > Remediation Hub, you can:

  • View workflow execution history directly in Remediation Hub.
  • Monitor execution status, including successful, failed, and in-progress runs.
  • Access generated artifacts and workflow outputs in a centralized location.

Top of page


Threat
Copy link

A threat is any potential event or action that could exploit vulnerabilities in a system, causing harm to assets, data, or operations. Threats can originate from various sources, including malicious actors, natural disasters, or unintentional human errors.

Control infostealer alert scope with the external user toggle
Copy link

In Digital Risk Protection (Threat Command), you can now control whether infostealer alerts include external user matches — credentials associated with a customer-owned domain but without an organizational email address. This gives security teams more control over alert volume without sacrificing visibility into employee credential exposure.

With this capability from Intelligence > DRP Configurations > Customization (or Configurations > Customization in Digital Risk Protection (Threat Command)), you can:

  • Toggle external user alerting on or off to refine infostealer alert scope.
  • Reduce alert noise by disabling monitoring of external email matches while continuing to monitor internal organizational emails.
  • Apply the setting to future alerts only, with no impact on existing or previously resolved alerts.

Top of page

Updated admin group identification for cloud identity providers
Copy link

In SIEM (InsightIDR), how cloud admin users are identified has been updated. Admin users from cloud identity providers such as Okta and Entra ID are now determined by membership in a group with a recognized admin role applied, rather than by group name alone. This change improves the accuracy of admin user identification across cloud environments.

Top of page

Improved AI-powered query generation
Copy link

We’ve enhanced AI-powered Log Search query generation to better understand natural language prompts and reduce the manual effort required to build searches.

It can now:

  • Automatically interpret natural language time expressions, such as “yesterday” or “last 24 hours”, and apply the appropriate time range to the search.
  • Suggest relevant log sources and event source types based on the intent of your prompt.
  • Provide a more detailed AI Query Explanation that includes the selected time range and log sources, making it easier to understand how your prompt was translated into a search query.

These improvements help you create more accurate searches faster while providing greater transparency into how AI interprets your requests.

Top of page

Improvements and Fixes
Copy link

Keep track of improvements and fixes to core technology.

Application Security (InsightAppSec) and AppSpider
Copy link

No updates released at this time.

Top of page

Attack Surface Management (Surface Command)
Copy link

Version 1.0.928
Copy link

Software release date: July 8, 2026 | Release notes published: July 13, 2026

Improved:

  • Connector update failures now include an Update Now button to facilitate immediate resolution.
  • The Connectors page now supports reviewing and applying multiple connector updates simultaneously.
  • Correlation Rules now display human-readable names and descriptions for automatic exclusion rules to improve clarity and usability.

Fixed:

  • Hostname and Domain filters now return matching records consistently across Network Services and Certificates pages.
  • The Test Connection button in Connector profile now displays a tooltip and disables when the test function is unavailable, preventing runtime errors.

Connectors

The following connectors were updated in the Extension Library  since the previous release. Connector updates are published independently and may have been available before this release date.

New Connectors

  • Nutanix Prism Central: Nutanix Prism Central is a centralized multi-cluster management plane that provides a single pane of glass for managing Nutanix infrastructure including virtual machines, hosts, clusters, networks, and images. This connector integrates with the Nutanix Prism Central v4 APIs to import infrastructure asset data into the Rapid7 Platform.

Updated Connectors

  • IGEL UMS: Fixed a schema validation error for the IgelUmsDevice type.
  • Microsoft Entra ID (formerly Azure AD): Added the AzureAdAppRoleAssignment type; app role assignments are now fetched as part of the applications feed.
  • SentinelOne Singularity: Added the new SentinelOneSoftwareInstallation type, linking per-agent installed software to SentinelOneSoftware.

Version 1.0.926
Copy link

Software release date: July 2, 2026 | Release notes published: July 6, 2026

Improved:

  • Executed queries now display 25 results instead of 10 for better readability.

Connectors

The following connectors were updated in the Extension Library  since the previous release. Connector updates are published independently and may have been available before this release date.

Updated Connectors

  • BigFix: Fixed a packaging error.
  • EZO AssetSonar:
    • Fixed schema type mismatches in EzoAssetSonarMember.
    • Added previously undeclared API fields to EzoAssetSonarAsset.
    • Pinned dependencies.
  • IGEL UMS: Fixed a schema validation error for IgelUmsDevice.
  • Kaseya VSA 10: Added Applied Policies enrichment with the M1051 (Update Software) mitigation.
  • Kaseya VSA 9: Added the M1051 (Update Software) mitigation to KaseyaVSA9Agent using the patch scan status API.
  • ManageEngine ServiceDesk Plus: Added schema validation for the ManageEngineServiceDeskUser type.
  • Matrix42 CMDB: Added Asset filter to only import assets with an operational status of Active.
  • Nozomi Vantage:
    • Added Nozomi certification headers (nn-app and nn-app-version) to all requests.
    • Added retry handling for API throttling responses (HTTP 429 and HTTP 503).
    • Improved vulnerability pagination and deduplication handling.
  • SolarWinds IT Asset Management: Fixed hostname correlation.

Top of page

Cloud Security (InsightCloudSec)
Copy link

Release availability for self-hosted users

Self-hosted users are able to download the latest version usually 4 business days after SaaS users are upgraded from the following locations:

  • Terraform deployments: Public S3 bucket . Modules can be updated with the terraform get -update command.
  • Amazon Elastic Container Repository (ECR) deployments: You can obtain the ECR build images for this version from the InsightCloudSec ECR Gallery 

Version 26.7.7
Copy link

Software release date: July 9, 2026 | Release notes published: July 9, 2026

Improved

  • Added background job OrphanedCredentialCleanup that removes orphaned cloud credentials daily or on-demand. These orphaned credentials are unused by harvesting or other portions of the product.

New Insights

  • Ensure EC2 Auto Scaling Groups Propagate Tags to Launched Instances (Insight ID 2582) - Detects AWS Auto Scaling Groups where one or more tags are not configured to propagate to the EC2 instances they launch. This aligns with CIS AWS Compute Services Benchmark control 2.14.
    • Supported Clouds: AWS, AWS China, AWS GovCloud.
    • Compliance Pack Mappings: CIS Controls v8.1.2 (1.1), NIST 800-53 Rev 5 (CM-8, CM-8(1), PM-5), NIST 800-171 (3.4.1, 3.4.9, 3.12.4), NIST CSF 2.0 (ID.AM-01, ID.AM-07), CMMC Level 2 (CM.L2-3.4.1, CA.L2-3.12.4).
    • After re-harvesting, Auto Scaling Groups will show tag propagation compliance status. Groups with no tags are considered compliant. Groups not yet re-harvested will show as “unknown” and will not trigger findings.
  • Volume Not Marked for Deletion on Instance Termination (Insight ID 2591) - Identifies EBS Volumes attached to EC2 Instances that are not configured for automatic deletion upon Instance Termination, helping reduce orphaned resources and potential data exposure. Aligned with CIS AWS Compute Services Benchmark Control 2.12.
    • Compliance Pack Mappings: CIS Controls v8.1.2, NIST SP 800-53 Rev. 5, NIST SP 800-171 Rev. 2, NIST CSF v2.0, and CMMC Level 2.
  • Instance Using Default Security Group - Identifies AWS EC2 Instances that are associated with a default security group rather than a specified custom security group.
  • Cloud Account Organization Without Tag Policy Enabled - Identifies management Cloud Accounts whose AWS Organization does not have Tag Policies enabled.

New Query Filters

  • Autoscaling Group Not Propagating Tags at Launch - Identifies Auto Scaling Groups where tags are not configured to propagate to launched instances.
    • Supported Clouds: AWS, AWS China, AWS GovCloud.
  • Cloud Account Organization Tag Policy Status - Identifies management Cloud Accounts based on Tag Policy enablement status at the Organization root.

New Compliance Pack

  • Added CIS Red Hat OpenShift Container Platform Benchmark v1.9.0 compliance pack.

Fixed

  • Fixed Cache Instance Auth Token Disabled Query Filter false positive. The filter now correctly inherits auth_token configuration.
  • Fixed Resource Associated With Public Subnet Query Filter to correctly detect ElastiCache public subnet associations in CloudFormation Template (CFT) scans.
  • Fixed an error that could cause IaC scan listing to fail with a database session error.
  • Fixed an issue where resources with exceptions were not showing on the misconfiguration UI and export.
  • Resolved intermittent Azure snapshot harvesting failures. Fixed an issue where the Azure snapshot harvester could intermittently fail with a NotImplementedError, preventing snapshot data from being collected during affected harvest runs.
    • The snapshot harvesting method is now defined directly on the Azure backend class, consistent with how all other cloud providers (AWS, GCP, AliCloud, Oracle) are implemented.
    • No changes to harvested data or behavior — runs that previously succeeded continue to work identically.

Top of page

Mimics Infrastructure as Code (IaC) Scanning Tool
Copy link

No updates released at this time.

Top of page

SIEM (InsightIDR)
Copy link

No updates released at this time.

Top of page

Vulnerability Management (InsightVM)
Copy link

Version 8.52.0
Copy link

Software release date: July 13, 2026 | Release notes published: July 13, 2026

Improved:

  • Improved Splunk Enterprise fingerprinting on Unix/Linux. Added a dedicated fingerprinter that detects Splunk Enterprise by querying the product directly for its version, replacing the previous OS package-based detection.This improves coverage for Splunk installations deployed outside the system package manager (e.g., tarball installs under /opt/splunk), resulting in more accurate software inventory and vulnerability assessment on affected hosts.
  • Added fingerprinting support for AI tools, MCP servers, and AI development skills, providing greater visibility into AI technologies deployed across your environment to help identify both authorized and unauthorized usage.
  • Added fingerprinting support for Microsoft Intune-managed applications. The scan engine can now detect and inventory software deployed and managed through Microsoft Intune (Microsoft Endpoint Manager), including Win32 apps, MSI line-of-business apps, and Microsoft Store for Business apps. This enhancement enables accurate software fingerprinting on Windows 10/11 endpoints enrolled in Intune, with proper version reporting that matches the Intune console. Duplicate software entries are reconciled when both a local installer and an Intune-managed installer are detected for the same application. Vulnerability assessments are automatically applied to discovered Intune-managed software where existing content coverage is available.

Fixed:

  • Resolved an issue where the scan engine incorrectly reported a Diffie-Hellman key size of 0 for TLS 1.3 services.
  • Fixed an issue where wildcard CVE searches in the General Search vulnerability tab could return incomplete or incorrect results. Wildcard prefix matching now behaves as expected.
  • Addressed an issue preventing reverse-paired Scan Engines from reconnecting automatically after a Security Console restart. Previously paired engines now reconnect as expected.
  • Fixed an issue that could cause PostgreSQL 15 major version migrations to fail during upgrade. Database migrations now complete successfully.

Version 8.51.0
Copy link

Software release date: July 7, 2026 | Release notes published: July 6, 2026

Improved:

  • Enhanced Oracle Access Management fingerprinting to improve patch version identification and reporting accuracy.
  • Improved scan logging for custom service names configuration issues, providing clearer messages when files are missing or cannot be parsed to simplify troubleshooting.
  • Strengthened the overall security posture of the Security Console by upgrading the bundled Axios library to the latest supported minor version.
  • Improved the performance and responsiveness of the Asset Search API, particularly for larger Security Console deployments.
  • Added built-in policy support for:
    • DISA STIG Microsoft SQL Server Database 2022 Benchmark V1R3
    • DISA STIG Microsoft SQL Server Instance 2022 Benchmark V1R4
  • Operating System Support: Added support for Microsoft Windows Server 2025 on the Vulnerability Management (InsightVM) Console, Nexpose Console, and Scan Engines.

Fixed:

  • Resolved an issue where the GET Scan Engine Sites API returned an incomplete value for scanTemplateName. The endpoint now returns the expected scan template name.
  • Fixed an issue where CSV vulnerability reports did not include tabular solution content, such as Windows Registry settings and configuration values. This information is now exported correctly.
  • Resolved an issue affecting Extensible Ingress when using a console proxy. Exposure Analytics traffic now correctly routes through the configured proxy, including authenticated proxies. A Security Console restart is required when using an authenticated proxy.

Top of page

Nexpose
Copy link

Nexpose Version 8.52.0
Copy link

Software release date: July 13, 2026 | Release notes published: July 13, 2026

Improved:

  • Improved Splunk Enterprise fingerprinting on Unix/Linux. Added a dedicated fingerprinter that detects Splunk Enterprise by querying the product directly for its version, replacing the previous OS package-based detection.This improves coverage for Splunk installations deployed outside the system package manager (e.g., tarball installs under /opt/splunk), resulting in more accurate software inventory and vulnerability assessment on affected hosts.
  • Added fingerprinting support for AI tools, MCP servers, and AI development skills, providing greater visibility into AI technologies deployed across your environment to help identify both authorized and unauthorized usage.
  • Added fingerprinting support for Microsoft Intune-managed applications. The scan engine can now detect and inventory software deployed and managed through Microsoft Intune (Microsoft Endpoint Manager), including Win32 apps, MSI line-of-business apps, and Microsoft Store for Business apps. This enhancement enables accurate software fingerprinting on Windows 10/11 endpoints enrolled in Intune, with proper version reporting that matches the Intune console. Duplicate software entries are reconciled when both a local installer and an Intune-managed installer are detected for the same application. Vulnerability assessments are automatically applied to discovered Intune-managed software where existing content coverage is available.

Fixed:

  • Resolved an issue where the scan engine incorrectly reported a Diffie-Hellman key size of 0 for TLS 1.3 services.
  • Fixed an issue where wildcard CVE searches in the General Search vulnerability tab could return incomplete or incorrect results. Wildcard prefix matching now behaves as expected.
  • Addressed an issue preventing reverse-paired Scan Engines from reconnecting automatically after a Security Console restart. Previously paired engines now reconnect as expected.
  • Fixed an issue that could cause PostgreSQL 15 major version migrations to fail during upgrade. Database migrations now complete successfully.

Nexpose Version 8.51.0
Copy link

Software release date: July 7, 2026 | Release notes published: July 6, 2026

Improved:

  • Enhanced Oracle Access Management fingerprinting to improve patch version identification and reporting accuracy.
  • Improved scan logging for custom service names configuration issues, providing clearer messages when files are missing or cannot be parsed to simplify troubleshooting.
  • Strengthened the overall security posture of the Security Console by upgrading the bundled Axios library to the latest supported minor version.
  • Improved the performance and responsiveness of the Asset Search API, particularly for larger Security Console deployments.
  • Added built-in policy support for:
    • DISA STIG Microsoft SQL Server Database 2022 Benchmark V1R3
    • DISA STIG Microsoft SQL Server Instance 2022 Benchmark V1R4
  • Operating System Support: Added support for Microsoft Windows Server 2025 on the Vulnerability Management (InsightVM) Console, Nexpose Console, and Scan Engines.

Fixed:

  • Resolved an issue where the GET Scan Engine Sites API returned an incomplete value for scanTemplateName. The endpoint now returns the expected scan template name.
  • Fixed an issue where CSV vulnerability reports did not include tabular solution content, such as Windows Registry settings and configuration values. This information is now exported correctly.

Top of page

Digital Risk Protection (Threat Command)
Copy link

Software release date: [June 19, 2026] | Release notes published: [July 6, 2026]

New:

  • You can now control whether infostealer alerts include external user matches — credentials associated with a customer-owned domain but without an organizational email address. The toggle is located under Configurations > Customization in Digital Risk Protection (Threat Command), or under Intelligence > DRP Configurations > Customization in the Command Platform. External user alerting is on by default, preserving existing behavior. When turned off, monitoring stops for external email matches while internal organizational email monitoring continues. This setting applies to future alerts only and has no effect on existing or previously resolved alerts.

Top of page

Rapid7 Agent (Insight Agent)
Copy link

Version 4.1.1 (Unchanged from previous release version)
Copy link

Fixed:

Resolved an issue in a third-party Go library that prevented some Rapid7 Agent (Insight Agent) capabilities from working as intended on devices with Apple M5 Pro and M5 Max chipsets. The following capabilities are now restored on affected devices:

  • Endpoint Protection and Ransomware Prevention
  • Agent-based Policy
  • Hosted Velociraptor
  • On-demand vulnerability scans

If Command Platform (Insight Platform)-managed agent updates are enabled, the Rapid7 Agent (Insight Agent) will automatically update the Endpoint Broker, Agent Core, and Hosted Velociraptor components. For more information, see Data collected by the Rapid7 Agent (Insight Agent)  and Command Platform (Insight Platform)-managed agent updates .

Top of page

Next-Generation Antivirus
Copy link

No updates released at this time.

Top of page

Ransomware Prevention
Copy link

No updates released at this time.

Top of page

Velociraptor
Copy link

Version 0.74.4.27
Copy link

Software release date: [July 8, 2026] | Release notes published: [July 8, 2026]

Fixed:

Resolved an issue in a third-party Go library that prevented the Rapid7 Velociraptor client from working as intended on devices with Apple M5 Pro and M5 Max chipsets. For more information, see the Rapid7 Agent Release Notes.

Top of page

Automation (InsightConnect)
Copy link

No updates released at this time.

Top of page

Rapid7 Network Sensor (Insight Network Sensor)
Copy link

Version 2.0.0.2
Copy link

Software released: June 4, 2026 | Release notes published: July 14, 2026

Improved:

  • Removed DPDK as a dependency and replaced it with custom thread-management and memory allocations, resulting in a 7.6% packet capture performance improvement.

  • Raised thread limit from 16 to 32, resulting in better performance on 100 Gbps sensors with sufficient hardware.

  • This release includes improvements to event throughput.

Fixed:

  • Fixed a bug where multicast flows would sometimes be assigned the wrong direction.
  • Fixed protocol detection accuracy for STUN and mDNS.

New Protocols:

  • WUDO: The sensor now detects the Windows Update Delivery Optimization (WUDO) protocol, which is used by Windows endpoints to share update content peer-to-peer across a local network.
  • Cohesity RPC protocol: The sensor now detects the Cohesity Remote Procedure Call (RPC) protocol, used by the Cohesity Data Protection and Security Platform.
  • Aerohive Mobility Routing protocol: The sensor now detects the Aerohive Mobility Routing protocol, used by Aerohive wireless infrastructure for access point coordination.

Top of page